Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 2,841 - 2,860 of 3,597 CVEs
CVE-2025-8668 CRITICAL - 9.4

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS.This issue affects Turboard: from 2025.07 through 11022...

Published: Feb 11, 2026
Source: NVD
CVE-2025-8025 CRITICAL - 9.8

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early abo...

Published: Feb 11, 2026
Source: NVD
CVE-2025-66277 CRITICAL - 9.8

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3350 build 202...

Vendor: QNAP Systems Inc.
Product: QTS, QuTS hero
Published: Feb 11, 2026
Source: NVD
CVE-2026-1357 CRITICAL - 9.8

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when wri...

Published: Feb 11, 2026
Source: NVD
CVE-2026-26009 CRITICAL - 9.9

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with template.create or tem...

Vendor: karutoil
Product: catalyst
Published: Feb 10, 2026
Source: NVD
CVE-2026-21531 CRITICAL - 9.8

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Vendor: microsoft
Product: azure_conversation_authoring_client_library
Published: Feb 10, 2026
Source: NVD
CVE-2026-1774 CRITICAL - 9.8

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

Vendor: npm
Product: @casl/ability
Published: Feb 10, 2026
Source: NVD
CVE-2026-23906 CRITICAL - 9.8

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind                            ...

Vendor: Apache Software Foundation
Product: Apache Druid
Published: Feb 10, 2026
Source: NVD
CVE-2025-11242 CRITICAL - 9.8

Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery.This issue affects Okulistik: through 21102025.

Vendor: Teknolist Computer Systems Software Publishing Industry and Trade Inc.
Product: Okulistik
Published: Feb 10, 2026
Source: NVD
CVE-2026-2096 CRITICAL - 9.8

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

Vendor: flowring
Product: agentflow
Published: Feb 10, 2026
Source: NVD
CVE-2026-2095 CRITICAL - 9.8

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.

Vendor: flowring
Product: agentflow
Published: Feb 10, 2026
Source: NVD
CVE-2026-0509 CRITICAL - 9.6

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentia...

Vendor: sap
Product: netweaver_as_abap_kernel
Published: Feb 10, 2026
Source: NVD
CVE-2026-0488 CRITICAL - 9.9

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impac...

Vendor: sap
Product: netweaver_application_server_abap
Published: Feb 10, 2026
Source: NVD
CVE-2026-25939 CRITICAL - 9.1

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA environments to follow-on...

Vendor: frangoteam
Product: FUXA
Published: Feb 09, 2026
Source: NVD
CVE-2026-25938 CRITICAL - 9.8

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has been patched in FUXA ve...

Vendor: frangoteam
Product: FUXA
Published: Feb 09, 2026
Source: NVD
CVE-2026-25881 CRITICAL - 9.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal protection flag through array literal intermediaries. When a global prototype reference (e.g., Map.prototype, Set.prototyp...

Vendor: nyariv
Product: SandboxJS
Published: Feb 09, 2026
Source: NVD
CVE-2026-25875 CRITICAL - 9.8

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-controlled JWT claims (role and scope) without enforcing server-side role verification.

Vendor: Praskla-Technology
Product: assessment-placipy
Published: Feb 09, 2026
Source: NVD
CVE-2026-25876 CRITICAL - 9.1

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). For example, this can be used to return all results for an assessment.

Vendor: Praskla-Technology
Product: assessment-placipy
Published: Feb 09, 2026
Source: NVD
CVE-2026-25810 CRITICAL - 9.1

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks).

Vendor: Praskla-Technology
Product: assessment-placipy
Published: Feb 09, 2026
Source: NVD
CVE-2026-25809 CRITICAL - 9.8

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission wi...

Vendor: Praskla-Technology
Product: assessment-placipy
Published: Feb 09, 2026
Source: NVD